How the guides are written and reviewed

Sixty guides and more than a hundred check explanations is a lot of text. This page sets out how it is produced, how it is kept accurate and what we will not do with it.

Purpose

Every guide exists to explain a check the scanners run or a decision a reader has to make after reading a report. We do not publish pages to capture search queries that have no connection to the tools. If a topic would not change what someone does with a scan result, it does not get a guide.

How guides are produced

  1. Scope. Each guide is assigned a single question and a single cluster. The hub for that cluster must be able to introduce it in one sentence.
  2. Drafting. Guides are drafted by the Security Desk with editorial tooling, including AI-assisted drafting for structure and first passes. Illustrations are generated with image models to a house style.
  3. Verification. Every claim about a standard, header, record or tool is checked against the primary source, which is then cited in the guide's source list: IETF RFCs, OWASP, MDN, NIST, CISA and vendor documentation. Numbers without a named source are removed.
  4. Position. Each guide has to recommend something. A guide that only lists options is sent back.
  5. Structural checks. An automated validator enforces minimum length, a direct answer at the top, worked examples, an FAQ, resolvable internal links and unique openings, so no two guides can be near-duplicates.

Bylines

Guides are credited to the Scan.now Security Desk rather than to invented individual authors. That is deliberate: The work is collaborative, and a fictional author with a fictional biography would be a misrepresentation. The about page describes who the desk is.

Updates and corrections

Each guide shows its publication and last-updated dates. Dates change only when the content changes. Errors reported through the contact form are checked within a week; material corrections are noted at the top of the affected guide. Guides about tools we reference are reviewed when those tools change behaviour.

Contributed articles

The blog carries contributed articles from the security community. They are labelled as contributed, reviewed for accuracy before scheduling, published no faster than one every three days, and are never used to place paid or affiliate links. They complement the guides; they do not replace them as the reference behind a check.

What we will not do